Troubleshooting: FIDO2 Authentication Fails

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: SecureAuth Identity Platform 22.02+
     
     

    Overview

    When using FIDO2 as a multi-factor authentication (MFA) method, users receive: "Authentication could not be completed. Please try again or choose another authentication method." A hardware security key such as a Yubikey enrolled for FIDO2 may instead show "This security key doesn't look familiar."

    Waiting for Your Approval screen showing the error Authentication could not be completed. Please try again or choose another authentication method, with a Learn more link and an option to use an alternate verification method.

     

    Cause

    There can be various reasons for this error. One common cause is that the fully qualified domain name (FQDN) the user used to enroll their security key does not match the FQDN of the realm they are authenticating against -- for example, enrolling at https://company.domain.com/SecureAuthxx but authenticating against an alias such as https://alias-for-my-company.domain.com/SecureAuthxx.

     

    Resolution

    To use security keys successfully, make sure the realm's FQDN is the same FQDN that was used when the device was enrolled.
     
     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.